CVE-2014-9773

HIGH

Atheme <7.2.7 - Command Injection

Title source: llm
STIX 2.1

Description

modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/03/1
Issue Tracking x_refsource_confirm
https://github.com/atheme/atheme/issues/397
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-05/msg00061.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/02/2

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (3)
atheme/atheme < 7.2.6
opensuse/leap 42.1
opensuse/opensuse 13.2
Published Jun 13, 2016
Tracked Since Feb 18, 2026